In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.2 or later, which disambiguates the resource-name collision.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NApache Airflow Providers Fab
APPApache< 3.7.2
Related vulnerabilities
Apache Airflow FAB: pominięcie weryfikacji podpisu tokenu OAuth (Azure AD)
Apache Airflow Providers FAB — nieprawidłowe wygasanie sesji (CWE-613)
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airfl...
Apache Airflow FAB Auth Manager zawiera podatność LDAP filter injection (CWE-90), która pozwala nieuwierzyteln...
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych